Working Student / Intern: Offensive Security Engineer (Red Team & AppSec) (f/m/x)
We hire for talent and a builder's mentality, not a checklist. If you have a writeup, a CTF profile, a disclosed vulnerability, or a tool you built — bring it. That tells us more than any certification will.
Attack Our Product: Pentest the ilert platform end to end — web app, public API, webhooks, and integrations. Hunt for what actually matters in multi-tenant SaaS: broken auth and authz, tenant isolation failures, IDOR, SSRF, injection, and abuse of our alerting and escalation logic.
- Red Team Our Infrastructure: Probe our cloud and Kubernetes configuration, secrets handling, CI/CD pipelines, and software supply chain. Find the path from "small misconfiguration" to "real access."
- Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team — always under a written scope signed off by the CTO before you start, always debriefed as a learning exercise, never punitive. Then help us fix what the exercise exposed.
- Break the AI, Too: We're building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection, tool abuse, and agent-boundary testing are wide-open ground here — and largely unexplored.
- Harden the SDLC: Bring dependency, secrets, and static analysis into CI where it earns its place. Threat-model new features with the engineers building them. Review the security-relevant PRs.
- Write Findings People Can Act On: A reproducible proof of concept, an honest severity call, and a concrete fix — then pair with the engineer who ships it. We care as much about closing the gap as finding it.
Current Student: Enrolled in Computer Science, IT Security, Informatics, or a related technical field.
- Demonstrable Offensive Work: Not coursework or certificates — things you've actually done. CTF results, HackTheBox/TryHackMe progression, bug bounty reports, a home lab you built, a writeup you published, a CVE you found. Show us one and walk us through it.
- You Can Read and Write Code: Enough to navigate a real codebase (we run Java, Rust, TypeScript/React), understand why a bug exists, and propose the fix — not just report that a scanner flagged something.
- Web Security Fundamentals: OWASP Top 10 as a working tool, not a memorized list. Authentication and session handling, access control, injection classes, SSRF, and what makes multi-tenancy hard.
- Comfortable With the Tooling: Burp Suite or equivalent, plus the usual recon and exploitation kit — and the judgment to know when manual beats automated.
- Judgment and Discretion: This role comes with access and trust. You stay inside the agreed scope, you don't test things you weren't authorized to test, and you handle what you find responsibly. Non-negotiable.
- Language: Fluent English (our working language).
Cloud or Kubernetes security, Infrastructure-as-Code scanning
- CI/CD and supply chain security (SAST, DAST, SCA, SBOM)
- LLM and agent security — prompt injection, tool-use boundaries, agent sandboxing
- Detection engineering: not just getting in, but noticing when someone else does
- German language skills
- A published CVE, security blog, meetup talk, or open source security tooling
Benefits
Cologne, Germany (Hybrid) Team: Engineering · Reports to: CTO · Format: Working Student (16–20h/week) or Internship (3–6 months) Location: Able to be in our Cologne office regularly — the role is hybrid, not remote. Bonus points
- A Real Attack Surface: Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.
- Build the Practice: You're the first security hire. What offensive security looks like at ilert is genuinely yours to define — with the CTO in your corner.
- Unexplored Ground: Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.
- Hybrid Freedom: Our office in Cologne Rheinauhafen (3 days/week) plus work from home (2 days/week).
- Student-Centric: Flexible hours around lectures and exam periods.
- Direct Mentorship: You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
- Focus Culture: We protect maker time, favor async, and keep meetings rare.
Keywords: Werkstudent IT-Security, Penetration Testing, Praktikum Cyber Security, Red Team, Application Security, Köln.